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AMENDMENTS TO CLAIMS 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

Listing of Claims: 

1. (Currently Amended) A method of detecting denial of service (DoS) attacks in an internet 
Internet accessible network having at least one proxy server incorporating a session initiation 
protocol (SIP) , said session initiation protocol includes INVITE (INV) messages that request set- 
up of an Internet telephone call and SIP 180 messages indicate ringing . comprising the steps of: 
detecting any substantial an imbalance between an accounting of said SIP INVITE (INV) and SIP 
180-(N^ Ringing messages resulting from a denial of service attack; and providing an 
indication of the presence of a current DoS attack on said proxy serve r based on detection of said 
imbalance . 

2. (Currently Amended) The method of detecting denial of service attacks in an intern e t Internet 
accessible network as defined in claim 1 wherein the number (H) of INVITE messages including 
credentials (INV c )-that are sent from a user client in response to an authentication required (407) 
message from the proxy serve r, said credentials being information used by the proxy server to 
authenticate the INVITE messages, are removed from the accounting before the balance is tested 
such that when the equation: 

INV G [[to]] + INV c -H = N 18 o 
where INV 0 is the number of INVITE messages without said credentials. INV C is the number of 
INVITE messages with said credentials, and N lg 0 is the number of said 1 80 messages, is not true 
within a small p redetermined margin of error a then the presence of a denial of service attack on 
the proxy server is indicated by the inequality. 
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3. (Currently Amended) The method of detecting denial of service attacks in an internet Internet 
accessible network as defined in claim 2 further including causing said proxy server to maintain 
a call information table for determining the value of H. 

4. (Canceled) 

5 . (Currently Amended) A system for detecting denial of service attacks against session initiation 
protocol elements in a internet an Internet accessible network having at least one proxy server, 
comprising means at wherein said proxy server includes means for determining if the number of 
INVITE messages including credentials (INV C ) sent to said proxy server from user clients in 
response to an authentication requirement and providing an indication of exceeds a 
predetermined level that indicates a DoS attack when the number of INVITE messages exceeds 
a predetermined l e v e l , said credentials being information used by the proxy server to authenticate 
the INVITE messages . 

6. (Currently Amended) A system for detecting denial of service attacks in an internet Internet 
accessible network having at least one proxy server incorporating session initiation protocol 
(SIP), comprising wherein said proxy server including includes means for detecting any 
substantial an imbalance between an accounting of SIP INVITE (INV) and SIP 180 Ringing 
messages and means pr oviding indication of that indicates the presence of a current denial of 
service attack on said proxy server. 

7. (New) A system for detecting denial of service attacks against session initiation protocol 
elements in an Internet accessible network as claimed in claim 5, wherein said means creates a 
call-info table for use in tracking said INVITE messages. 

8. (New) A system for detecting denial of service attacks against session initiation protocol 
elements in an Internet accessible network as claimed in claim 6, wherein said means creates a 
call-info table. 
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